18 June 2011

FCPA Alert: Dodd-Frank vs. Powerball...

Board Directors are ever more tuned into the recent 2011 case settlements in Foreign Corrupt Practices Act (FCPA) violations. This is because Operational Risk Professionals are being much more proactive than years past on uncovering malfeasance in the supply chain operations of major global conglomerates:

Notable 2011 FCPA Settlements. 2010 was a record year for FCPA enforcement, and thus far 2011 has been no different. In the first half of 2011, 10 notable FCPA enforcement actions have settled, resulting in a total of about $490 million in penalties, disgorgement and prejudgment interest:

1. Tenaris agreed to pay a $3.5 million criminal penalty and $5.4 million in disgorgement and prejudgment interest.

2. Rockwell Automation agreed to pay disgorgement of $1.7 million, prejudgment interest of $590,000 and a civil penalty of $400,000.

3. Johnson & Johnson agreed to pay a $21.4 million criminal fine and $48.6 million in disgorgement and prejudgment interest, as well as about $7.9 million in related United Kingdom Serious Fraud Office recovery.

4. Comverse agreed to pay a $1.2 million criminal fine and $1.6 million in disgorgement and prejudgment interest.

5. Ball Corporation agreed to pay a $300,000 civil penalty.

6. Jeffrey Tesler, a key member of the TSKJ-Bonny Island joint venture accused of being part of a scheme to bribe Nigerian officials in exchange for contracts related to the construction of liquefied natural gas facilities, forfeited nearly $149 million, the largest FCPA-related forfeiture imposed on an individual to date.

7. JGC Corporation of Japan agreed to pay $218.8 million in criminal fines.

8. IBM agreed to pay a $2 million civil penalty, disgorgement of $5.3 million and $2.7 million in prejudgment interest.

9. Tyson Foods, Inc. agreed to pay a $4 million criminal penalty and $1.2 million in disgorgement and prejudgment interest.

10. Maxwell Technologies agreed to pay $8 million in criminal penalties, as well as $6.4 million to settle SEC civil charges.


Are any Board Directors out there amazed that companies such as IBM are still being impacted by the FCPA risk to the enterprise? Maybe more importantly, why is a Japanese company paying a criminal fine of over two hundred million dollars?

JGC CORPORATION is a Japan-based company mainly engaged in the engineering business. The Company operates in two business segments. The Integrated Engineering segment is engaged in the planning, design, procurement, construction and testing of equipment, appliances and facilities for petroleum, petroleum processing, petrochemistry, gas, liquefied natural gas (LNG), general chemistry, nuclear energy, metal smelting, biotechnology, food, pharmaceutical, logistics, information technology, environment protection and pollution prevention industries. This segment is also engaged in the provision of related inspection, maintenance and information processing services, as well as water and power generation business, among others. The Catalyst and Chemical segment is involved in the manufacture and sale of catalyst agents, functional materials, deodorants and enzymatic filters, electronic materials and high-performance ceramic products, as well as next-generation energy related products.

The Board of Directors of any transnational organization should be doing their homework on the reasons why JGC Corporation has employed an independent compliance consultant for the next two years and paid the $200M. fine. Remember, your supply chain and your business partners may be the reason why you are sitting around the Board Room table negotiating with the U.S. Department of Justice.

The larger question is, could this have been prevented? Is this a risk that can be mitigated within the corporate enterprise? Has the company done everything in it's capacity to put the right controls in place and the tools to keep the possibility of FCPA ever finding its way back to the Board Room Agenda? Do you know all of your joint venture partners are from the U.S. and all of the projects that they are working on together?

JGC’s agreement to pay the fine brings to $1.5 billion the total penalties in a case against a joint venture known as TSKJ that included Houston-based Kellogg Brown & Root LLC, Paris- basedTechnip SA (TEC) and Dutch engineering firm Snamprogetti Netherlands BV, according to a Justice Department statement.

The joint venture’s prosecution represents one of the biggest foreign bribery cases undertaken by the Justice Department since it stepped up pursuit of such cases starting in 2008 when Munich-based Siemens, Germany’s largest engineering company, paid $1.6 billion to settle U.S. and German probes.

“Each of the four companies in the TSKJ joint venture, the former chairman of the U.S. joint venture partner, and several other individuals have now been held accountable for a massive conspiracy to bribe Nigerian government officials to obtain lucrative construction contracts,” Deputy Assistant Attorney General Mythili Raman said in the statement.


What is the cost of a FCPA investigation beyond the fine? Imagine for a moment the number of e-mail messages that have to be acquired, preserved and examined. Add up the billable hours for subject matter experts to review the remaining mountain of data to determine the final relevancy of a communication with the matter and the people associated with the project. As an example, what was the magnitude of the Siemens case?

According to court records, it was a vast undertaking spanning 34 countries, with private investigators conducting more than 1,750 interviews and gathering more than 100 million documents. They reviewed approximately 14 million of those documents and gave the Justice Department and the SEC a small subset, about 24,000, according to a Siemens tally.


So what is one of the answers or solutions to finding the "Red Flags" and to self-disclose the issue to the proper authorities early and often? First off, you need to develop your corporate "Human Intelligence" (HUMINT) capability, around your Corporate Intelligence Unit (CIU). Developing and building an awareness factor in a pervasive manner is one way to do this. In order to get your HUMINT working for you, the people on the front lines and in the middle of the corporate hierarchy need to understand and internalize these "Red Flags". If the monthly or quarterly bulletin from the CEO, discussing the integrity factor of the company supply chain partners raises the issue of ethical behavior around a particular scenario, this will educate and increase awareness with those people in the enterprise who comprise this HUMINT network.

Sticks and carrots or other methods for awarding compliance is so 1980's and 1990's. Wake up! In order to bring your global enterprise into the next decade of the 2000's, you have to start using the methods, processes and tools your deal makers use to run their business (SAP, Siebel CRM, Oracle). When was the last time the CEO visited the deal makers pipeline meeting to review and discuss the joint ventures or pending projects that the business developers are forecasting to close in the next quarter? This is the perfect time for the CEO to ask them to fire any partner, agent, consultant, contractor or vendor that does not meet the foundation for the companies "Corporate Integrity Standards." Does your CEO even know what Social CRM is all about?

And how quickly the lessons that should have been learned, are soon forgotten. Not any more. Under the Dodd-Frank Wall Street Reform and Consumer Protection Act, employees, partners and other persons who provide original information on an FCPA violation by a public company can receive between 10% and 30% of the resulting fines as a "Whistleblower" bounty.

We wonder whether the odds of winning the next "Powerball" Lottery in the U.S. might be more difficult than getting 20% of a $200 million dollar fine. Global corporations should be preparing their internal processes for Ethics and Integrity Management now. This Operational Risk will soon be more apparent as employees understand the odds of "Winning".

28 May 2011

OPSEC: TQM in the Defense Industrial Base...

OPSEC in the Defense Industrial Base (DIB) is on high alert since the RSA SecureID vulnerability was revealed several months ago. The Operational Risks Management discipline is now ever so pervasive in private sector companies who have outsourced national security programs. When top secret information is at risk, the game plan shifts from a single company incident to a federal priority.

By Jim Finkle and Andrea Shalal-Esa

BOSTON/WASHINGTON, May 27 (Reuters) - Unknown hackers have broken into the security networks of Lockheed Martin Corp (LMT.N: Quote, Profile, Research, Stock Buzz) and several other U.S. military contractors, a source with direct knowledge of the attacks told Reuters.

They breached security systems designed to keep out intruders by creating duplicates to "SecurID" electronic keys from EMC Corp's (EMC.N: Quote, Profile, Research, Stock Buzz) RSA security division, said the person who was not authorized to publicly discuss the matter.

It was not immediately clear what kind of data, if any, was stolen by the hackers. But Lockheed's and other military contractor networks house sensitive data on future weapons systems as well as military technology currently used in battles in Iraq and Afghanistan.



The SecureID hack has been an eye opening wake up call for those Operational Risk professionals who are charged with keeping information safe from foreign adversaries. The "One-Time-Password" (OTP) market place is gearing up for a dramatic shift. Organizations such as EMC the parent to RSA are still back pedaling from the crisis and cooperating with three letter U.S. agencies to determine the culprits. Not only do organizations such as Lockheed Martin hold the nations major weapons systems contracts they are also prime contractors for defending the cyber security networks across the government.

So what is the answer for keeping the nations states across the globe from continuously probing and successfully compromising secret systems networks by hacking tools like the SecureID?

The answer lies within the private sectors approach to quality assurance in software development. The vulnerability that all security-based companies and defense industrial based companies face is the flaws in software quality assurance practices. The known fact is that in any process for software development there is a testing phase to determine whether the product requirements have been satisfied. In the lifecycle of software development, the QA testing phase is still the most neglected and under staffed. Raising the bar on software quality testing is not the only answer, it is just a facet of the security mosaic that continues to be a major challenge.

Total Quality Management (TQM) initiatives not only should be mandated by software development organizations, the Defense Industrial Base needs to require new levels of software code testing by companies that are charged with securing the secrets of the company and the nation. As each new product or software version is launched into the marketplace it should have a label on it that discloses how diligent the vendor was in testing the software for defects. Reducing those defects before it lands in the hands of the consumer is one major path to reducing the vulnerabilities of such serious breaches of trade secret or national security information.

Like natural ecosystems, the cyber ecosystem comprises a variety of diverse participants – private firms, non‐profits, governments, individuals, processes, and cyber devices (computers, software, and communications technologies) – that interact for multiple purposes. Today in cyberspace, intelligent adversaries exploit vulnerabilities and create incidents that propagate at machine speeds to steal identities, resources, and advantage. The rising volume and virulence of these attacks have the potential to degrade our economic capacity and threaten basic services that underpin our modern way of life.



What will soon be the norm in the software development industry is the TQM mind-set that has been at the forefront of other manufacturers for decades. Once the regulators get the gears rolling the private sector will finally change and work towards "Six Sigma" in software in combination with more effective approaches to Operational Risk Management:

The approach to managing operational risk differs from that applied to other types of risk, because it is not used to generate profit. In contrast, credit risk is exploited by lending institutions to create profit,market risk is exploited by traders and fund managers, and insurance risk is exploited by insurers. They all however manage operational risk to keep losses within their risk appetite - the amount of risk they are prepared to accept in pursuit of their objectives. What this means in practical terms is that organisations accept that their people, processes and systems are imperfect, and that losses will arise from errors and ineffective operations. The size of the loss they are prepared to accept, because the cost of correcting the errors or improving the systems is disproportionate to the benefit they will receive, determines their appetite for operational risk. Events such as the September 11 terrorist attacks, rogue trading losses at Société Générale,Barings, AIB and National Australia Bank serve to highlight the fact that the scope of risk management extends beyond merely market and credit risk.

As OPSEC evolves in the Defense Industrial Base, the risk appetite and TQM conversation will continue to be on the agenda. The degree to which it makes it to the Board Rooms of EMC, still remains to be seen.

22 May 2011

Battle of Narratives: Fukushima to Abbottabad...

The U.S. Energy companies are getting ready for an audit report on their facilities after the Fukushima Daiichi nuclear plant disasters in Japan. The results will not be an Operational Risk Management executives favorite topic, across the Board Room table of Pacific Gas & Electric (PG&E), Entergy and Duke. In the aftermath of any disaster such as the earthquake in Japan, or the financial economic armageddon of 2008 spawned by greed and unregulated markets, the auditors reports will uncover the vulnerabilities in the mechanisms for industry oversight.

Vulnerabilities found at dozens of U.S. reactors

By PETER BEHR of ClimateWire

Something under one-third of the 104 U.S. reactors were found to have some vulnerabilities to extreme emergencies, according to the NRC, which is preparing a summary of its post-Fukushima findings.

The NRC says that all issues have been fixed or put on schedule for correction, and that the safety of the reactors was not compromised.

PG&E spokesman Paul Flake said issues reported by the NRC had been identified by the company's own review after Fukushima, and an inspection by the Institute for Nuclear Power Operations, the industry's confidential safety monitor.


Information and the transparency of information will continue to be at the center of investigations on wall street or the energy industry. "Who knew what when" is the mantra being repeated in various command posts and within task forces who are responsible now for insuring the safety and security of future employees of these firms but also the national security of the country. Insider Risk of leaked information is at an all time high whether you are in the "C" suite in Manhattan or the "Situation Room" on Pennsylvania Avenue. Josh Rogin of Foreign Policy explains the predicament in Washington over the raid on Usama Bin Laden's compound in Abbottabad, Pakistan:


The nation's top civilian and military defense officials are calling on their government colleagues to shut up about the details of the May 1 raid in Pakistan that killed Osama bin Laden.

Defense Secretary Robert Gates and Joint Chiefs Chairman Adm. Mike Mullen held their first press conference on Wednesday since the mission to kill bin Laden. Gates stood by a remark he made May 12 at Camp Lejeune, in which he said there was an agreement by top Obama officials in the Situation Room to not reveal details of the raid -- but that the agreement fell apart the next day.

"My concern is that there were too many people in too many places talking too much about this operation. And we had reached agreement that we would not talk about the operational details, and as I said at Camp Lejeune, that lasted about 15 hours," Gates said on Wednesday. "And so I just -- I'm very concerned about this because we -- we want to retain the capability to carry out these kinds of operations in the future. And when so much detail is available, it makes that both more difficult and riskier."

Neither Gates nor Mullen called out any Obama administration officials by name, but Mullen, sounding even more frustrated, implied that the breaches of security by administration officials are ongoing and still a problem to this day.


The energy industry in the U.S. is now under the magnifying glass just as the banks, mortgage companies, brokers and hedge funds have been scrutinized since the financial meltdown over mark to market and predatory lending practices. The Nuclear Regulatory Commission is akin to the Securities and Exchange Commission as the federal agency who has oversight and jurisdiction when it comes to keeping the country safe and secure from private industry misdeeds or mistakes.

Information is the lifeblood of any highly functioning organization whether in the private sector or government agencies. Protecting that information of leaks to third parties who do not have a need to know is the crux of the "Insider Trading" cases on Wall Street or even the comments made within the confines of the situation room during Bin Laden's operation. So why do people want to tell another person something that they know is forbidden? Why do they risk sharing information with the media or others who may not have a legitimate reason to know the information?

And what about the opposite? Withholding information from the public or others who have a need to know the information especially if it will save lives or keep the country out of harms way. The decisions to tell or withhold information has serious consequences in either case and requires a mechanism for making sure that humans know when it is right and wrong. Unfortunately, we live today in a world of information warfare and information operations that spans the globe from Hollywood to Kabul or London to Hong Kong.

The "Human Factors" motivation for withholding or sharing information has been studied for decades if not hundreds of years. The gratification one receives from telling another a secret only known to one person or a few provides the stimulus. Whether that human gratification is the result of seeing someone else in pain or suffering, surprise or elation doesn't really matter. Recognizing that humans thirst for information is relentless when it comes to being first, or to gain power can provide you with the understanding to better prepare your organization for "Information Operations" (IO):

"A Theory of Conflict and Cooperation Model" that describes how each actor is attempting to expand, protect, or exploit existing powerbases through cooperative or conflicting relationships with other local actors. Vol. 2 Issue 3 August 2010 IO Journal


Effective Operational Risk Management begins with understanding information and ends with protecting or sharing information. It's your challenge to determine what is real and what is just another narrative to influence your perception as a human being.

08 May 2011

Vigilance: Risk After Bin Laden...

Usama Bin Laden is no longer a risk to the operations of many high value targets across the globe. Yet, now that he is dead, the distributed network of followers may soon carry out his blueprints for destruction. Large U.S. conglomerates doing business overseas are on high alert announced from their 24 x 7 Crisis Operations and Security Risk Management centers.

The raid on Osama bin Laden's compound yielded a trove of intelligence the size of a small college library, a top White House official said Sunday.

In a series of coordinated news-show appearances National Security Adviser Tom Donilon said information seized during last week's killing of the Al Qaeda leader represents the largest cache ever obtained from a terrorist. He said it indicates that in addition to being the group's symbolic leader, bin Laden was involved in strategic operations, including Al Qaeda's propaganda effort.


Al Qaeda's network is decentralized and therefore more resilient to defeat. It will not simply disappear by having one of it's founding leaders gone forever. Corporate institutions who have their American citizens in distant high risk countries such as Algeria, Pakistan, Philippines, Iraq, Mexico, Venezuela, Nigeria, Kenya, Sudan are on heightened alert. Kidnapping is now even more of a risk in these countries especially in rural areas.

At the speed of business in 2011, the infrastructure companies have found new opportunities to build out energy and telecommunications projects using the latest "Green" and "Wireless" technologies. The threat and risk to those who represent the enemy in the eyes of Al Qaeda include the U.K. and the growth of "Homegrown Violent Extremists" (HVE) in America:

To date, cells detected in the United States have lacked the level of sophistication, experience, and access to resources of terrorist cells overseas. Their efforts, when disrupted, largely have been in the nascent phase, and authorities often were able to take advantage of poor operational tradecraft. However, the growing use of the Internet to identify and connect with networks throughout the world offers opportunities to build relationships and gain expertise that previously were available only in overseas training camps. It is likely that such independent groups will use information on destructive tactics available on the Internet to boost their own capabilities.

Operational Risk Management professionals have watched the unfolding information in Abbottabod and realized one thing. Our vigilance is now more important than it has ever been in the past ten years. The preparation, training, exercises and intelligence collection is increasingly more justified and vital. These simple 4 steps in this continuous process shall be even more integrated into the fabric of our corporate and institutional landscapes:

  • Deter
  • Detect
  • Defend
  • Document

This "4D" strategy will provide your employees with the kind of mindset necessary to help keep them safe and secure from unknown future adversaries. They may be coming from the outside while on a foreign business trip overseas or within the confines of your own headquarters in Chicago, Illinois. Complacency is our largest and most active threat today. Let the death of Usama Bin Laden and the turmoil unfolding in the Middle East remind us to continue our Operational Risk Management missions.

Remember people like Pat Tillman, Michael P. Murphy, OP Restrepo, Jeremy Wise, Dane Paresi, Scott Roberson, Elizabeth Hanson, Tim Hetherington, and Lara Logan who continues the fight. Their courage and sacrifice will never be forgotten...

13 February 2011

Digital Domains: Threats to Nation States and Corporate Board Rooms...

The last two plus weeks the planet Earth has witnessed the use of Digital Social Media to help facilitate the overthrow of the 30 year reign of Hosni Mobarak in Egypt. Is this the last example of how the use of the Internet combined with the masses of humanity can overthrow government leadership? The Operational Risk to nations states and the implications of the impact on business, commerce and political outcomes is increasingly being subjected to the new digital influence of social networking apps.

(CBS) The revolution in Egypt was historic not only for toppling President Hosni Mubarak after 30 years, but for revealing the awesome power social media had amassed - enough to be the instrument that inspired hundreds of thousands of people already staunchly opposed to the regime to rise up and act as one.

Now the questions are already being asked - can social media's power be used that way again and if so, where and when?

The protesters In Egypt were mobilized largely via the use of Facebook and Twitter, over 18 long days.

Special Section: Historic Change in Egypt

The revolt there is already being dubbed the Social Media Revolution.

It started Jan. 25, with a call-to-action -- from a Facebook page dedicated to Khalid Said, an Egyptian businessman who was beaten to death by police last summer after threatening to expose police corruption.

Millions of Egyptian youth are big users of Facebook, and saw the page.

Over time, a few prominent faces emerged from the masses. One, Google executive Wael Ghonim, identified by Mubarak's government as the creator of that first Facebook page, was detained.

But the movement had already gained momentum.

Facebook and Twitter, said one protester, "It's a very good way for communication. It has no power or control from anyone."

Now that the US State Department has established a Twitter feed in Arabic, the odds are that the strategy to more effectively communicate US policy to the muslim world will grow. The risks associated with the speed of communications via the Internet and the "Ground Truth" situational awareness have forever changed the meaning of an "Intelligence-led" enterprise. The continuous news cycles fueled by the masses will provide the Fortune 500 executives and the nations states world leaders with the sentiment of their brand, their policy or their reputation at the touch of a personal "Blackberry" or "iPhone."

What has not changed however, is the requirement for increased confidentiality, integrity and assurance of information whether that be streaming from the US State Department feed or the public relations department of a company such as Cisco. Will human behavior begin to migrate from reading the latest official press releases or the Facebook and Twitter feeds to better understand the current state of affairs on the company. The answer is both. It will just be a matter of what lens you want to look through to determine the truth about a subject or situation with the organization that you are investigating.

The information integrity conversation is ongoing from the board room to battle field. How do you continuously insure that the Intel or the digital data you are receiving is the truth and not changed along the path to the leaders decision support consoles? Monitoring the information streams within an organization is not only a strategic necessity, it is a survival requirement.

The company that runs the Nasdaq stock market said Saturday that hackers had penetrated a service that handles confidential communications between public companies and their boards.

The service run by Nasdaq OMX Group Inc. carries strategic information for about 300 companies. The company said it appears no customer data was compromised.

Nasdaq OMX said the hacking attempts did not affect its trading systems. Nasdaq is the largest electronic securities trading market in the U.S. with more than 2,800 listed companies.

The targeted application, Directors Desk, is designed to make it easier for companies to share documents with directors between scheduled board meetings. It also allows online discussions and Web conferencing within a board.

Since board directors have access to information at the highest level of a company, penetrating the service could be of great value for insider trading. The application's Web page says "Directors Desk provides multiple layers of security to protect our clients' most vital corporate records."

The Digital Domains will continue to be threats to Nations States and Corporate Board Rooms for years and decades to come.

07 February 2011

LEO: The Economics of Remote Digital Forensics...

At the speed of the modern global enterprise, cyber incidents are a growing component of operational risk, according to 1SecureAudit Managing Director and Chief Risk Officer Peter L. Higgins. Digital forensics intelligence provides analysts, investigators and management the ability to make more informed decisions regarding a prudent course of action. Utilizing digital evidence can mean the timely detection of unethical behavior by an employee or the intelligence nexus with kidnapping, child pornography, industrial espionage or terrorism. The legal process in a specific state or country and the preservation of evidence, chain of custody and even early case assessment are now a converging area of concern with local and state law enforcement, prosecutors and defense law firms.

"The 1SecureAudit Digital Forensics Practice capitalizes on the Digital Forensic POD powered by Evidence Talks Ltd. Our systems enable our team of subject matter experts to work on clients cases across the country or across the world," said Higgins. "Our certified professionals using the Digital Forensics POD gives a client quick access to resources that can help with an investigation without the high cost of flying people across the country or the globe."

"A good lesson learned from my first-hand experience in Afghanistan is that we depend on support back home from subject matter experts to help our soldiers remotely without the need to be in the actual combat zone," said Cristian Balan (CISSP, CHFI) of NY Computer Networks.

"We recognized that many police agencies, as well as law firms, needed an affordable solution to help clear up their digital forensics back log," said Craig Cantwell, SVDFL Forensics Laboratory Director. "By teaming up with 1SecureAudit and Cristian Balan and using our remote digital forensics POD systems, we are able to offer more clients a better economy of scale and service at a price that they can justify."

Counselors initial conferences and additional motions for discovery during litigation results in the need for additional digital forensics capacity. The Digital Forensics POD assists with case backlog especially as court dates approach rapidly or many cases at the same time. "We are excited to be working with Peter Higgins and the team at 1SecureAudit, as well as Cristian Balan of NY Computer Networks who brings his full Digital Forensic and Incident Response capabilities to the team," said Cantwell.

1SecureAudit has assembled a team of professionals that are ready to work on clients cases for a secure and timely response. With the advent of Remote Digital Forensics powered by Evidence Talks, the level of service and responsiveness that first responders can provide has increased tenfold. The firm's MetaLogic early case assessment services will ensure both civil and criminal cases are ready for an initial meeting with the legal teams. FlexResponse professional services ensures that client have the additional expertise available on demand as a case unfolds. The law enforcement organization, state or county prosecutors and private law practice now has access to experts across the country or the world at a moment's notice.

For more information visit RemoteForensics.us (http://www.RemoteForensics.us) or e-mail Dispatch@RemoteForensics.us.

30 January 2011

Crisis Management: ORM & Public Relations Convergence...

Operational Risk Management Executives will be tuning into CBS 60 Minutes Sunday night. If you are a Bank of America stakeholder and your stock dropped 3% on November 30, 2010 because of a WikiLeaks document release, this episode should be on your mind:

(Reuters) - WikiLeaks founder Julian Assange says he enjoys making banks squirm thinking they might be the next targets of his website which has published U.S. diplomatic and military secrets.

"I think it's great. We have all these banks squirming, thinking maybe it's them," Assange told the CBS television program "60 Minutes" in an interview.

CBS released a partial transcript on Friday ahead of Sunday's broadcast of the full segment.

Bank of America Corp shares fell more than 3 percent on November 30 on investor fears that the largest U.S. bank by assets would be the subject of a document release.

Interviewer Steve Kroft asked Assange whether he had acquired a five-gigabyte hard drive belonging to one of the bank's executives, as Assange had previously asserted.

"I won't make any comment in relation to that upcoming publication," said Assange, who is under a form of modified house arrest in England, awaiting an extradition hearing to Sweden for questioning over alleged sex offences that he denies.



WikiLeaks will not be the last whistleblower web site to provide the dirty laundry on what a government agency or public company may or may not be doing as it does it's daily business. The CBS or TMZ media mechanisms remain the outlet for an information economy that fuels the behaviors of modern day paparazzi or contributors to WikiLeaks and it's future competitors.

What are Operational Risk Managers thinking about when these loss events happen? Another lost or stolen laptop by one of the thousands of corporate executives is now a major incident, not one to be taken lightly, perhaps as it has in years past. This is also why these same managers are working in a diligent strategy to emphasize the use of products that will encrypt the whole hard drive on the mobile systems that are being toted around in taxi cabs and on airplanes. The thought of a loss of these tools will be less of an issue as these programs are implemented and every bit of every data on these mobile devices is now encrypted.

The External Affairs, Public Relations and Corporate Communications strategy for a Fortune 500 company is extensive. With Social Media becoming a major component of the Web 2.0 integration and the booming number of PDA's, iPhones and other mobile devices, "Crisis Management" and "Operational Risk" will continue to be two disciplines that need each other more than ever.

Bank of America will survive just as others have before it once the information is released and people have a chance to determine how damaging it could be or not worth the hype to pay attention to it. What will perpetuate beyond the latest PR crisis is the fact that the speed of data, videos, Tweets and Blogs continues to pile up on the hard disks, Jump Drives, IronKeys and servers in "The Enterprise Cloud." How you manage it, secure it and dispose of data is an Operational Risk that will not diminish any time soon.

Who has seen the light when it comes to the utilization of Cloud Computing, and effective document encryption in transit with embedded information security compliance standards? Uncle Sam for one.

WASHINGTON – The U.S. General Services Administration announced today that federal, state, local, and tribal governments will soon have access to cloud-based Infrastructure as a Service (IaaS) offerings through the government’s cloud-based services storefront, Apps.gov. GSA’s IaaS contract award allows vendors to provide government entities with cloud storage, virtual machines, and Web hosting services to support a continued expansion of governments’ IT capabilities into cloud computing environments.

“Offering IaaS on Apps.gov makes sense for the federal government and for the American people. Cloud computing services help to deliver on this Administration’s commitment to provide better value for the American taxpayer by making government more efficient,” said federal Chief Information Officer Vivek Kundra. “Cloud solutions not only help to lower the cost of government operations, they also drive innovation across government.”


The use of new technologies or platforms such as these only provides the Operational Risk Professional with new found ways to mitigate risks, not eliminate them. Therefore, whether you are the CIO at B of A or part of the Federal CIO Council in the United States the fact remains that people will continue to use lost or leaked information to their advantage. This is a threat to the enterprise no different than the loss of power, catastrophic fire or natural disaster. When you have a known threat out there such as WikiLeaks, then you now realize that this must be addressed in your vulnerability assessments and your risk management planning.

Google Apps is now FISMA Certified. Whether the number of incidents increases or diminishes will still remain with the behavior of people and the ability for OPS Risk management to continue to be part of the executive conversation on the risks of data getting into the wrong hands. With this being an inevitable situation, the convergence of crisis management, PR and media communications will increasingly become part of the Enterprise Risk Management team. Let's just hope they keep a seat for the 28 year old IT staffer who supports the implementation of their enterprise apps and the exponential growth of their information cloud.

22 January 2011

Digital Paradox: Privacy v. Security...

The media communications and advertising industries are buzzing over the new U.S. Federal Trade Commission report and framework entitled: Protecting Consumer Privacy in an Era of Rapid Change. The Operational Risk Management implications to your enterprise could be significant if you currently do not understand how your marketing department provides disclosures or manages consumer collected data. If you think that you are protected because you outsource to a 3rd party, then think again. The power to the consumer is increasing and the data privacy laws are playing a quick game of catch-up on regulation:

Scope: The framework applies to all commercial entities that collect or use consumer data that can be reasonably linked to a specific consumer, computer, or other device.

Companies should promote consumer privacy throughout their organizations and at every stage of the development of their products and services.

With 500 Million plus people who are self-profiling themselves on Facebook these days, you might wonder if they even truly think about their privacy. See Controlling How You Share, Facebook
A variety of business models involve practices that fall outside the proposed “commonly accepted practices” category. These include, for example, a retailer collecting purchase information directly from a consumer and then selling it to a data broker or other third party that may be unknown to the consumer. Other examples include online behavioral advertising, in which an online publisher allows third parties to collect data about consumers’ use of the website, as well as social media services, where the service or platform provider allows third party applications to collect data about a consumer’s use of the service. In addition, as noted above, using deep packet inspection to create marketing profiles of consumers would not be a commonly accepted practice.

The new framework and panel discussions has focused on the Operational Risks associated with collecting, storing and sharing data on consumers. The regulations that change going forward to assist in consumer protections and disclosures may not have much impact on whether the consumers "Personal Identifiable Information" (PII) is disclosed to nefarious transnational criminal syndicates without their permission.

If you are a U.S. government military employee you may have received notice lately from your PenFed Credit Union that you too may have your PII in the hands of people that will use it for monetary gain. The continuous loss of data by institutions has now been verified as just another criminal business enterprise by organized crime and in many cases sanctioned by nation states. The data protection and data theft game is the modern equivalent of bank robbery yet it is moving at the speed of electrons across fiber optic networks world wide.

And now that this accelerating consumer issue of cybersecurity has made it's way to The White House, one can only wonder what may change. The cost to business is now $204.00 per record according to well respected research by Ponemon Institute. The MOU with DHS, Department of Commerce and the Financial Services Sector Coordinating Council (FSSCC) remains the window dressing on another unfunded effort to deter the cyber plague before us.

There is no shortage of people reporting about the breaches (this blog included), the hacks and the data leakage via employees using Peer 2 Peer file sharing software within the walls of their Fortune 500 company or government agency. Some people who are disclosing the information are doing it with alternative motives and rarely try to provide a potential solution to the problem.

So what can a PenFed or major U.S. Government agency do, to stem the tide of the growing digital tsunami of data thefts and transnational economic crime or acts of espionage? There is not one solution nor is there ever going to be a day when it all comes to an end. Which brings us to the mind set shift that is necessary to make a difference.

The Security vs. Privacy legal topic is somewhere in the mix of the solution. The education of our digital natives at a young age is another. Many kids know how to type with their thumbs better than they can write a legible letter to grand mother. And finally, the implementation of new technologies that will enable law enforcement to their jobs more effectively.

Now back to the mind set shift. Cecilia Kang of the Washington Post reports:

As the United States looks at ways to better protect Internet users’ privacy, Europe is going through its own update of online privacy rules. The 27-nation European Union is taking a more aggressive approach to privacy by setting higher bars for how data can be collected on Web users.

European laws prohibit Web sites from tracking users without their permission. The E.U. is also weighing legislation that would let users delete all their information from a Web site, such as Facebook, and transfer data from one wireless provider to another without leaving profiles behind.

Viviane Reding, the vice president of the E.U. Justice Commission and head of privacy regulation, visited The Post on Wednesday to talk about her approach to protecting users in the age of Internet over-sharing. On Thursday, she is scheduled to meet with U.S. Attorney General Eric Holder to discuss ways the E.U. and U.S. can cooperate on safeguarding consumers' personal information, including data on travel and finances. The talks may also touch on the recent disclosure of classified documents by Wikileaks.


09 January 2011

Cyber Theft Rings: A Nexus with Terrorism...

BSA/AML compliance is an Operational Risk that continues to plague even the largest institutions. The ability to effectively program information systems to address "Politically-Exposed Persons" (PEP) and the risk to the banks reputation are still a challenge for some executives.

Why is this still an OPS Risk issue? In many cases, the lack of procedures being followed by adequate staff in the alert investigations unit where backlogs are prevalent. This becomes a business risk because there continues to be a lack of closure on these alerts. The simple monitoring of funds transfers to ensure timely reporting of suspicious activity associated with PEP's should be AML 101.

Retaining and deploying an independent consultant to review compliance and systems controls is the primary responsibility of an Audit Committee chair of the Board of Directors. For those institutions that have found themselves under the recent oversight of the OCC in the United States, many realize they have underfunded this obligation and the staff requirements to stay in pace with the expanding volume of electronic transactions.

Monitoring accounts of current or former senior political figures is well within the PEP definition and includes their families and any close associates. Therefore, the BSA officer will require even more robust budgets, staffs and systems programming to continue to be effective in regulatory compliance of the Bank Secrecy Act and Anti-Money Laundering statutes. And this just covers the risks associated with the banks regulatory obligations in the United States and many other countries of the world.

Yet this is the area that has traditionally been the foundation for the 20th century criminals and other entities who need to move money to places in large sums or to perpetuate fraudulent activities. Now what about the 21st century asymmetric threat, "Cyber Theft Rings"?

Malware exploiters purchase malware on the black market Internet and use it to steal victims banking credentials. They launch attacks from systems that are already compromised across the globe in small businesses and other commercial or government organizations. This allows the transnational cyber criminal to transfer stolen funds and deter the tracking of their activities. Money Mule networks then transfer funds to other accounts or get cash from ATM's and then buy stored value cards before they ship them back overseas to the crime syndicates.

The victims remain the financial institutions and the owners of the infected systems. So how large is this method of cyber theft? In 2010 the FBI reported close to 400 cases that had attempted loss of $220M and actual losses of $70M.

Today's (October 1, 2010) coordinated operation demonstrates that these 21st-century bank robbers are not completely anonymous; they are not invulnerable. Working with our colleagues here and abroad, we will continue to attack this threat and bring cyber criminals to justice."

Most of the accused hailed from Eastern Europe; many were based in Ukraine, where several worked as Web developers. Ten suspects were arrested in New York on Thursday, with another 10 having been arrested previously. The FBI is still seeking 17 others .


Where is the money going and what is it being used for? In a recent study by officials at the New York State Intelligence Center titled: "The Vigilance Project: An Analysis of 32 Terrorism Cases Against the Homeland", the statistics are the face of the US challenges with money laundering and terrorism:

  • 82 % were between the ages of 18 and 33.
  • 61 % attended some college and of these 64% of the educated terrorists were engineering majors.
  • 50 of the 80 suspects in the study whose citizenship could be identified were born in the U.S. .
  • 11 of the 32 cases studied happened in the past two years. In these cases, 17 of the 19 defendants were in the United States legally.
The banking community understands that it has to remain vigilant when it comes to BSA/AML regulations. Not only to avoid the millions of dollars in potential fines, but also because of the potential nexus with counterterrorism.

31 December 2010

Denial: Resolution for a New Year...

On the eve of the New Year, 2011 approaches with new perspectives and new found learning on the risks before us. Operational Risk is about managing "All Hazards" and "All Crimes" whether you are working within the ranks of the largest global 500 organization, or managing self as J. Q. Citizen. OPS Risk is just not about a government or corporate perspective any longer and is becoming more personal for many professionals in their daily lives. Managing their families, their households and the risks associated with spouses, parents, siblings and even those who you don't even know. But they know you.

In Dr. Jessica Stern's latest book "Denial: A Memoir of Terror" you will find that her story is very much about your own personal operational risk management. It will transport you into thoughts about all of the ways that people can learn about you and your personal life through good old fashioned surveillance or today on Facebook or Twitter. Yet this isn't about this new age phenomenon of digital stalkers or voyeurs. This story is about "Denial" and the risk of denial in the context of observation or your own behavior and the others who surround you.

"Denial is almost irresistibly seductive, not only for victims who seek to forget the traumatic event but also for those who observe the pain of others and find it easier to ignore or "forget." In the long run, denial corrodes integrity--both of individuals and of society. We impose a terrible cost on the psychically wounded by colluding in their denial."
In this skillfully wrought, powerful study, a terrorism expert, national security adviser (The Ultimate Terrorists), and lecturer at Harvard, returns to a definitive episode of terror in her own early life and traces its grim, damaging ramifications. Having grown up in Concord, Mass., in 1973, Stern, then 15, and her sister, a year younger, were forcibly raped at gunpoint by an unknown intruder; when the police reopened the case in 2006, Stern was compelled to confront the devastating experience. The police initially tied the case to a local serial rapist, who served 18 years in prison before hanging himself. Stern's painful journey takes her back to the traumatic aftershocks of the rape, when she began to affect a stern, hard veneer not unlike the stiff-upper-lip approach to survival her own German-born Jewish father had assumed after his childhood years living through Nazi persecution. Covering up her deep-seated sense of shame with entrenched silence, Stern had a classic post-traumatic stress disorder—which she was only able to recognize after her own work interviewing terrorists. Stern's work is a strong, clear-eyed, elucidating study of the profound reverberations of trauma.

Dr. Stern brought to light in her process of interviewing people, that "Denial" can be a true "Operational Risk" in itself. How many times have you observed someone's behavior and thought to yourself, that doesn't feel right. How many times have you said to yourself, this behavior is not good for my own well-being? This self-talk is something that all of us need to pay more attention to, as we embark on this New Year and the next decade of the 21st century.

What behavior have you witnessed lately that you are in denial about? Make a New Year's eve wish, pledge or resolution that this has to end. What ever the behavior that has occurred or will soon occur, the risks are too great to remain in denial. The trauma that exists in your mind or the potential impact that a future trauma may have, can be managed from a risk management point of view. What is the likelihood and the impact to you, your organization or your friends and family?

As we all watch the ball drop tonight at 12:00 midnight in the USA in Times Square New York City, reflect on the 2010 risks that you took by continuing to be in denial. Think about all of those people you encounter everyday at work, in the local grocery store and even in your own neighborhood. Open your eyes and your mind to the behaviors that just don't seem right. Manage your risk exposure when it comes to the people you associate with and the people who are watching you, without your knowledge.

The contributor(s) to this Operational Risk Management blog wish you a Happy and Prosperous New Year!

03 December 2010

Remote Digital Forensics: OPSEC Continuous Monitoring...

What do Operational Risk Management, continuous monitoring and "Remote Digital Forensics" Intelligence have in common? The digital age is challenging the global enterprise and the speed and depth of new found transnational threats requires bold outside-of-the-box thinking. Strategic decisions to prevent incidents of data leakage, theft of trade secrets or corporate espionage are on the minds of CEO’s and the Office of the General Counsel.

An organizations ability to proactively deter, detect and defend it’s vital corporate assets requires a focused lens to view the vast digital complexities and simultaneously gain deeper insights. Effective risk management in Global 500 companies encompasses the collection, analysis and action on relevant information. Is the relevant information stored on a mobile laptop, network attached desktop or mobile PDA? Could there be a copy of the document on the server in the form of an e-mail attachment? The objective seems obvious. Think a few steps ahead in order to mitigate the quantity and size of potential loss events where and when they will happen.

In order to achieve a “Game Changing” strategy to stay one step ahead of today’s digitally equipped adversary demands an adaptive process, tools and very smart people. Timely and accurate intelligence-led investigations have historically proven to save many organizations from catastrophic impact to their reputation. That is precisely why Digital Forensics Intelligence (DFI) has been gaining tremendous momentum with the Chief Risk Officer, Chief Security Officer, Chief Information Officer and the General Counsel. One example, is the ability for an organization to add forensic intelligence to almost any investigation, to provide additional dimensions of insight and to ascertain whether an employee is a true insider threat or just in non-compliance with your latest “Acceptable Use Policy.”

Corporate Digital Forensics Intelligence provides the corporate first responders with the potential evidence required by analysts, investigators and decision makers to make more informed decisions. The ability to more effectively determine a prudent course of action, can mean the difference between detecting a simple Internet policy violation or the beginning of a prolonged investigation with a corporate espionage nexus. The legal process in your state or country and the preservation of evidence, chain of custody and even early case assessment are now a converging area of concern with the office of the General Counsel and outside retained law firms.

“Achieving A Defensible Standard of Care” in your organization requires a digital risk governance framework that will withstand the tests of local law enforcement and judicial systems, inspector generals and global federal investigations. Remote and SPEKTOR Digital Forensics Triage has been gaining momentum with corporate enterprise, law enforcement and military investigators for years.

The reason is that certain kinds of investigations can't wait for days, weeks or a month to gain insight and evidence on the digital data stored on a suspects laptop, desktop or PDA. With the legal corporate policy in place or search warrants the fast Digital Forensics Triage process allows First Responders to quickly examine and determine what digital assets need to be seized and those that do not have any major "Red Flags". This keeps the corporate Digital Forensics Lab or RCFL from being overburdened with devices that hold no relevancy to a particular case and therefore minimizes the mountain of unexamined digital evidence.

The use of both Digital Forensic Triage and Real-Time Network Forensics solutions directly addresses the compliance requirements in the US Government for "Continuous Monitoring."

How can organizations address advanced persistent cyber threats?

To address the advanced persistent cyber threat requires a multi‐pronged effort by organizations. First, it requires a major change in strategic thinking to understand that this class of threat cannot always be kept outside of the defensive perimeter of an organization. Rather, this is a threat that in all likelihood, has achieved a foothold within the organization. This situation requires that organizations employ methods to constrain such threats in order to ensure the resiliency of organizational missions and business processes. Second, it requires the development and deployment of security controls that are intended to address the new tactics, techniques and procedures (TTPs) employed by adversaries (e.g., supply chain attacks, attacks by insiders, attacks targeting critical personnel). NIST Special Publication 800‐53, Revision 3, includes many new security controls and enhancements (most not selected in any of the control baselines) that are specifically intended to address some of these TTPs. Finally, to enable cyber preparedness against the advanced persistent cyber threat, organizations must enhance risk management and information security governance in several areas.

These include, but are not limited to: (i) development of an organizational risk management and information security strategy; (ii) integration of information security requirements into the organization’s core missions and business processes, enterprise architecture, and system development life cycle processes; (iii) allocation of management, operational, and technical security controls to organizational information systems and environments of operation based on an enterprise security architecture; (iv) implementation of a robust continuous monitoring program to understand the ongoing security state of organizational information systems; and (v) development of a strategy and capability for the organization to operate while under attack, conducting critical missions and operations, if necessary, in a degraded or limited mode.

Operational Risk Management calls for a robust and smart Information Governance Framework whether you are a Global Enterprise or a National Government. As the international WikiLeaks aftermath unfolds it will finally unveil the facts about "How" this incident could have happened. What is certain today is that the answer does not lie with new technology or tools. Human Factors and social engineering will always have the upper hand.